Capture defects without capturing PII.
Auto-redaction for sensitive inputs, immutable audit logs, and SSO/SCIM for the access controls your auditor expects.
What hurts today
- Sensitive form data must never leave the client.
- Auditors expect immutable logs of every privileged action.
- Identity provider must be the source of truth for access.
- Vendor risk reviews stall when the feedback tool can't produce a DPA or sub-processor list on demand.
How AnchorMark fits
Marked inputs are blurred in screenshots and stripped from console payloads.
Every privileged write recorded with API export to your SIEM.
WorkOS-powered identity with group-derived role assignment.
Public sub-processor list, a DPA on request, and a tenant-isolation smoke test that runs in CI.
A current DPA is available for execution; sub-processors are listed publicly.
Frequently asked questions
Where is data stored?
Can I require SSO for all members?
How do you keep PII out of screenshots?
data-anchormark="redact" and the SDK blurs them in the captured frame and strips them from console payloads. Workspace-wide redaction rules apply policy without per-page configuration — see security & compliance.Do you have SOC 2?
Can I export the audit log to my SIEM?
Do you sign a DPA?
How fast does deactivation propagate when an employee leaves?
Keep exploring
Tenant-first architecture, encrypted storage, and audit logs built for modern web teams.
Enterprise sign-on with SAML and OIDC, plus SCIM provisioning to keep teams in lockstep with your identity provider.
Every report ships with the screenshot, console errors, network failures, browser, OS, and viewport — captured automatically.
A documented OpenAPI surface and webhook events for comments, mentions, status changes, and project events.
Loop executives and customers into approval flows without giving them a tracker seat or training.